FBI issues water infrastructure cyber-attack warning
Key Highlights
- The FBI issued a PSA warning on water infrastructure cyber-attacks.
- Malicious cyber actors are targeting internet-connected PLCs in water and other critical facilities.
- Authorities advise asset owners to adopt layered security measures to protect critical control systems from malicious cyber threats.
The Federal Bureau of Investigation (FBI) and Environmental Protection Agency (EPA) issued a Public Service Announcement (PSA) warning of critical water infrastructure cyber attacks.
Asset owners and operators are warned that malicious cyber actors (MCAs) are conducting attacks targeting Operational Technology (OT) devices including Rockwell Automation/Allen-Bradley Programmable Logic Controllers (PLCs) and specifically MicroLogix 1100 and 1400 series. These PLCs are also commonly used in food and beverage facilities, chemical processing plants, and oil and gas systems/plants.
Since July 27, 2026, Water and Wastewater Sector (WWS) utility companies in at least seven states have reported incidents to the FBI, and some of that activity degraded water operations. While the FBI has only observed this behavior with the referenced Rockwell PLCs, similar considerations should also be made with other branded PLCs.
MCAs are targeting internet-exposed PLCs (Rockwell Automation/Allen-Bradley’s MicroLogix 1100 and 1400 series) to remotely tamper with device configurations by changing IP addresses and turning on and setting passwords, resulting in a loss of view, and in some cases, function of connected equipment in targeted facilities.
At least one organization reported modified PLC project files after noticing ladder logic discrepancies across several sites. Additionally, across several victims, similarities in network setup provided by third parties may provide MCA the opportunity to multiply successes when vulnerable network and hardware setups exist across customers.
Operational effects reported to the FBI have included loss of pressure and flooding. Pressure loss in water systems could potentially allow untreated ground water to seep into pipes. Once compromised, the extent of impact to victims’ operations depended upon the type of function for which the PLC was configured (monitoring versus controlling equipment), the equipment itself (1100 versus 1400), the function the device supported, and capability to switch to manual operations.
To reduce the risk of compromise, the FBI and EPA recommend removing PLCs from direct internet exposure via secure gateway and firewalls, setting up strong, unique passwords, and utilizing an access control list (ACL) to allow only authorized communication between expected control system devices. More detailed recommendations are given in the FBI PSA.
